Quantcast
Channel: Questions in topic: "universal-forwarder"
Viewing all articles
Browse latest Browse all 1551

Why are fields not being extracted using props.conf on my universal forwarder?

$
0
0
Hi, I have been using a props.conf file to extract fields in my event logs, but it does not seem to be working. Below are the sample props.conf and event. Any help is much appreciated. C:\Program Files\SplunkUniversalForwarder\etc\apps\my_app\local\props.conf [Script:WinService] EXTRACT-service = SERVICE_NAME: (?\S*) EXTRACT-state = STATE\s*?: [0-9]\s*(?\S*) and the event is shown in attached image. Many thanks in advance. Regards, Rajnish Kumar

Viewing all articles
Browse latest Browse all 1551

Trending Articles